Problem AuthnContextClassRef with Comparison="exact"
Domenico Cervino
cervinodomenico at libero.it
Mon Mar 4 15:41:20 UTC 2024
Thanks Scott but there was a misunderstanding, the behavior described in your answer is exactly what we would like to happen, which we expected to happen, but we don't understand why it doesn't happen. Sorry if our english is unclear we are using google translate.
We want the first method to be "acceptable", our problem is that only the first method is acceptable.
The anomaly we encounter with idp4 is that only the first in the list is considered. With the idp2 it worked exactly as we wanted and as you described (in or).
Referring to the example given, the behavior of SP_2 it's OK for us, the behavior of SP_3 it's our problem.
Thanks
Domenico
> Il 04/03/2024 16:21 CET Cantor, Scott <cantor.2 at osu.edu> ha scritto:
>
>
> > Is there something in the configurations that we may not have configured
> > correctly when moving to idp v4?
>
> No. If you don't want the first method to be "acceptable", don't request it. SAML defines the full set as an OR, not an AND. If you send >1, then any of them are acceptable, so stopping once one is possible to satisfy is the obvious behavior to implement.
>
> There is a setting that behaves more like V2 did, but it is not advisable and you certainly can't count on that semantic from other IdPs.
>
> -- Scott
More information about the users
mailing list